{
  "name": "Operation HollowQuill: Russian R&D Networks Targeted via Decoy PDFs",
  "slug": "operation-hollowquill-russian-rd-networks-targeted-via-decoy-pdfs",
  "description": "Operation HollowQuill targets Russian research and defense networks, particularly the Baltic State Technical University, using weaponized decoy documents disguised as research invitations. The attack chain involves a malicious RAR file containing a .NET dropper, which deploys a Golang-based shellcode loader and a legitimate OneDrive application. The final payload is a Cobalt Strike beacon. The campaign focuses on academic institutions, military and defense industries, aerospace and missile technology, and government-oriented research entities within the Russian Federation. The threat actor employs sophisticated techniques, including anti-analysis measures, APC injection, and infrastructure rotation across multiple ASNs.",
  "published": "2025-03-31T10:20:31+00:00",
  "created_at": "2025-03-31T10:20:31+00:00",
  "modified_at": "2025-03-31T13:56:45+00:00",
  "created_at_opencti": "2025-03-31T10:20:31+00:00",
  "author": "",
  "confidence": null,
  "report_types": [],
  "labels": [],
  "tags": [
    "2025-03-31",
    "academic institutions",
    "baltic state technical university",
    "cobalt strike",
    "decoy pdfs",
    "defense industry",
    "operation hollowquill",
    "russian r&d",
    "shellcode loader"
  ],
  "related_entities": {
    "observables": [
      {
        "id": "",
        "name": "https://phpsymfony.com/css3/index2.shtml"
      },
      {
        "id": "",
        "name": "pariaturzzphy.makebelievercorp.com"
      }
    ],
    "malware": [
      {
        "id": "ab138766-9b64-4880-87fb-1942a709d778",
        "name": "Cobalt Strike - S0154",
        "slug": "cobalt-strike-s0154"
      }
    ],
    "attack_patterns": [
      {
        "id": "dcdb439a-a7ce-4b60-8f9f-469a0acf7ba5",
        "name": "T1055.004"
      },
      {
        "id": "c998d878-b668-40dd-a84c-9ca7f73caaa4",
        "name": "T1497.003"
      },
      {
        "id": "6f00068c-812c-4e2b-9100-2cfa86b3aed9",
        "name": "T1132.001"
      },
      {
        "id": "40f0d8e3-bcd7-4b97-a958-f55815698fc5",
        "name": "T1053.005"
      },
      {
        "id": "5999052b-e9ae-49e8-9235-d9bf975c22af",
        "name": "T1547.001"
      },
      {
        "id": "196f2a64-c55b-47a6-8e38-beb76ba700b6",
        "name": "T1204.002"
      },
      {
        "id": "dc410646-9cdd-427b-92e7-179a54f78f90",
        "name": "T1566.001"
      },
      {
        "id": "7d7ac733-6442-416f-8669-c302dd0843b9",
        "name": "T1036"
      }
    ],
    "others": [
      {
        "id": "",
        "name": "Russian Federation"
      },
      {
        "id": "",
        "name": "Aerospace"
      },
      {
        "id": "",
        "name": "Defense"
      },
      {
        "id": "",
        "name": "Education"
      },
      {
        "id": "",
        "name": "Government"
      }
    ]
  },
  "external_refs": [
    "https://www.seqrite.com/blog/operation-hollowquill-russian-rd-networks-malware-pdf/",
    "https://otx.alienvault.com/pulse/67ea888fa30c32d310f46b3c"
  ]
}